Dne torek, 12. september 2017 ob 20:14:11 CEST je Zavras, Alexios napisal(a):
> For even more extreme fun, I can point to cases like ffmpeg, where,
> according to the options get passed to configure build script, different
> files (under different licenses) get compiled and linked.
Great example.
Mark,
You said 'A package is a “box of stuff” where some stuff may be related by
linking while other stuff is not.' While I agree that is true, I am not
sure I agree that dealing with it at a file level avoids many problems. For
two reasons: 1) wheather lawyers and licensing nerds like it or not
On Tue, Sep 12, 2017 at 02:52:26PM +, Wheeler, David A wrote:
> Mark Gisi:
> > the SPDX identifier model will need to accommodate a LicenseRef
> > like mechanism...
>
> I'm not arguing to *remove* licenserefs, I agree they can be useful.
>
> My point is different. Since many users *only* use
Mark Gisi:
> LicenseRefs are critical for creating SPDX files.
I disagree, for at least two reasons:
1. A vast amount of software does *NOT* require weird special-case licenserefs.
2. Many people who use SPDX will never see nor use a SPDX file. Instead, many
people use SPDX *exclusively* for
W. Trevor King [mailto:wk...@tremily.us]
Sent: Monday, September 11, 2017 2:27 PM
To: Gisi, Mark
Cc: J Lovejoy; Marc Jones; SPDX-legal
Subject: Re: GPLv2 - Github example
On Mon, Sep 11, 2017 at 08:59:17PM +, Gisi, Mark wrote:
> If the source file license is GPL-2.0 that currently means only
ce" examples that have a
fundamental problem with regards to the "or later"/only problem. The problem
appears to lie with package level licensing
-Original Message-
From: W. Trevor King [mailto:wk...@tremily.us]
Sent: Monday, September 11, 2017 2:27 PM
To: Gisi, Mark
Cc: J
frequently encountered in the wild.
- Mark
-Original Message-
From: Wheeler, David A [mailto:dwhee...@ida.org]
Sent: Monday, September 11, 2017 1:58 PM
To: Gisi, Mark; W. Trevor King
Cc: SPDX-legal
Subject: RE: GPLv2 - Github example
W. Trevor King:
> >> But you can't def
: Monday, September 11, 2017 12:18 PM
To: Gisi, Mark
Cc: J Lovejoy; Marc Jones; SPDX-legal
Subject: Re: GPLv2 - Github example
On Mon, Sep 11, 2017 at 07:04:57PM +, Gisi, Mark wrote:
> >> With the ‘only’ operator proposal [1], this situation can be
> >> represented by ‘CDD
W. Trevor King:
> >> But you can't define a LicenseRef in sitations (like npm [1]) where
> >> the only thing you can set is a license expression and you don't have
> >> access to the broader SPDX spec.
> >> [1]: https://docs.npmjs.com/files/package.json#license
>
Gisi, Mark:
> This is not a
On Mon, Sep 11, 2017 at 08:26:56PM +, Gisi, Mark wrote:
> >> But you can't define a LicenseRef in sitations (like npm [1]) where the
> >> only
> >> thing you can set is a license expression and you don't have access to the
> >> broader
> >> SPDX spec.
> >> [1]:
17 12:18 PM
To: Gisi, Mark
Cc: J Lovejoy; Marc Jones; SPDX-legal
Subject: Re: GPLv2 - Github example
On Mon, Sep 11, 2017 at 07:04:57PM +, Gisi, Mark wrote:
> >> With the ‘only’ operator proposal [1], this situation can be
> >> represented by ‘CDDL-1.0 only’.
>
>
On Mon, Sep 11, 2017 at 07:04:57PM +, Gisi, Mark wrote:
> >> With the ‘only’ operator proposal [1], this situation can be
> >> represented by ‘CDDL-1.0 only’.
>
> … Finally this case can be elegantly handled with a LicenseRef…
But you can't define a LicenseRef in sitations (like npm [1])
rovide a practical justification for adding an "only"
operator. Other Suggestions?
- Mark
-Original Message-
From: W. Trevor King [mailto:wk...@tremily.us]
Sent: Monday, September 11, 2017 10:30 AM
To: Gisi, Mark
Cc: J Lovejoy; Marc Jones; SPDX-legal
Subject: Re: GPLv2 - Github e
On Mon, Sep 11, 2017 at 03:40:05PM +, Gisi, Mark wrote:
> I know that the following CDDL was discussed with respect to the
> “only” problem:
>
> * This file and its contents are supplied under the terms of the
> * Common Development and Distribution License ("CDDL"), version 1.0.
> * You may
>> it’s the job of SPDX to provide a clear way to identify
>> what is found and a language to express that in.
I concur. Sometimes the best one can do is to document the lack of license
information hence the existence of the NONE and NOASSERTION designations.
Because a core SPDX principle is
15 matches
Mail list logo